PT-2026-96930 · Unknown · Mcp-Attlasian

CVE-2026-77267

·

Published

2026-09-22

·

Updated

2026-09-28

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mcp-atlassian versions prior to 0.22.0
Description The UserTokenMiddleware extracts URLs from the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url HTTP headers and passes them to API client constructors without validation. Specifically, the process authentication headers() function processes these headers to construct Atlassian fetchers without calling validate url for ssrf(). This allows a caller to supply internal or metadata-service URLs, causing the server to send requests to those destinations. This behavior enables Server-Side Request Forgery (SSRF), a condition where an attacker forces a server to make requests to an unintended location, such as AWS instance metadata or internal services.
Recommendations Update mcp-atlassian to version 0.22.0 or later. Validate all user-supplied URLs against an allowlist of permitted hostnames or reject private, loopback, and link-local IP ranges. Require server-side configuration of allowed Atlassian instance URLs.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77267
GHSA-5WF4-JQXH-8GM3

Affected Products

Mcp-Attlasian